Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
193421 7.5 重要
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおける ATD 検出を回避される脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2017-4055 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
193422 8.8 重要
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-4054 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
193423 9.8 緊急
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2017-4053 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
193424 9.8 緊急
Network
マカフィー - McAfee Advanced Threat Defense の Web インターフェースにおける認証を回避される脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2017-4052 2017-08-1 16:05 2017-07-11 Show GitHub Exploit DB Packet Storm
193425 7.3 重要
Local
Foxit Software Inc - Foxit Reader および PhantomPDF における任意のコードを実行される脆弱性 CWE-123
任意の場所に任意の値を書き込み可能な状態
CVE-2017-10994 2017-08-1 15:30 2017-07-4 Show GitHub Exploit DB Packet Storm
193426 6.1 警告
Network
WP Statistics - WordPress 用 WP Statistics プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-10991 2017-08-1 15:30 2017-07-7 Show GitHub Exploit DB Packet Storm
193427 9.8 緊急
Network
Irssi - Irssi における解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2017-10966 2017-08-1 15:30 2017-07-5 Show GitHub Exploit DB Packet Storm
193428 7 重要
Local
Google - Android の ActivityManagerService の bindBackupAgent メソッドにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2014-7953 2017-08-1 15:30 2014-09-10 Show GitHub Exploit DB Packet Storm
193429 7.5 重要
Network
Schneider Electric - Schneider Electric Wonderware ArchestrA Logger における NULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2017-9631 2017-08-1 13:58 2017-06-30 Show GitHub Exploit DB Packet Storm
193430 9.8 緊急
Network
Schneider Electric - Schneider Electric Wonderware ArchestrA Logger におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-9629 2017-08-1 13:58 2017-06-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3081 8.7 HIGH
Network
- - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML direct… CWE-79
Cross-site Scripting
CVE-2026-28445 2026-05-23 03:27 2026-05-23 Show GitHub Exploit DB Packet Storm
3082 10.0 CRITICAL
Network
- - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Re… CWE-862
CWE-918
 Missing Authorization
Server-Side Request Forgery (SSRF) 
CVE-2026-33712 2026-05-23 03:27 2026-05-23 Show GitHub Exploit DB Packet Storm
3083 6.5 MEDIUM
Network
- - Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter CWE-22
Path Traversal
CVE-2026-36227 2026-05-23 03:27 2026-05-23 Show GitHub Exploit DB Packet Storm
3084 7.3 HIGH
Network
- - Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality CWE-120
Classic Buffer Overflow
CVE-2026-36228 2026-05-23 03:27 2026-05-23 Show GitHub Exploit DB Packet Storm
3085 7.3 HIGH
Network
- - An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2026-37470 2026-05-23 03:27 2026-05-23 Show GitHub Exploit DB Packet Storm
3086 6.1 MEDIUM
Network
- - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… - CVE-2026-42506 2026-05-23 03:16 2026-05-23 Show GitHub Exploit DB Packet Storm
3087 6.1 MEDIUM
Network
- - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo… - CVE-2026-42502 2026-05-23 03:16 2026-05-23 Show GitHub Exploit DB Packet Storm
3088 8.8 HIGH
Network
ivanti secure_access_client An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. CWE-295
Improper Certificate Validation 
CVE-2026-8992 2026-05-23 02:50 2026-05-23 Show GitHub Exploit DB Packet Storm
3089 7.1 HIGH
Network
mattermost mattermost_server Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and down… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-3473 2026-05-23 02:21 2026-05-22 Show GitHub Exploit DB Packet Storm
3090 4.3 MEDIUM
Network
mattermost mattermost_server Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allow… CWE-200
Information Exposure
CVE-2026-3636 2026-05-23 02:21 2026-05-22 Show GitHub Exploit DB Packet Storm